Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
requests beautifulsoup4
- Confidence
- 95% confidence
- Finding
- requests
Security checks across malware telemetry and agentic risk
This skill is a straightforward public tender-announcement scraper with dependency hygiene issues but no evidence of hidden access or harmful behavior.
Install only from a trusted package index and consider pinning requests to a current vetted version before use. Expect the skill to make outbound requests to ygcg.nbcqjy.org and return public procurement notice data.
requests beautifulsoup4
requests beautifulsoup4
66/66 vendors flagged this skill as clean.